---
title: "Getting Started | ShipSafe"
description: "Install ShipSafe CLI, run your first security scan, and connect to your dashboard in under 5 minutes."
doc_version: 2026-10-05
last_updated: 2026-10-05T07:18:36.789Z
canonical: https://ship-safe.co/docs/getting-started
---

# Getting Started | ShipSafe

Getting Started

# Getting Started

Go from zero to your first security scan in under a minute. No signup required for local scans.

## Run Your First Scan

Point ShipSafe at any directory. It works with JavaScript, TypeScript, Python, Go, Ruby, Java, PHP, Rust, C#, Swift, and Kotlin.

TERMINAL

Copy

```bash
npx @ship-safe/cli scan .
```

No install needed. npx downloads and runs it in one command.

## What You Get

A free scan runs every pattern check we have — all 19 of them:

Hardcoded secrets & API keys

SQL, NoSQL & command injection

Cross-site scripting (XSS)

Path traversal & unsafe file access

Server-side request forgery (SSRF)

Open redirects

CORS misconfiguration

Mass assignment

Insecure deserialization

Weak crypto & JWT flaws

Supabase & Firebase exposure

Security headers & cookie flags

CSRF protection

PII in logs & responses

Dependency risk, including AI-hallucinated packages

AI agent config (Cursor auto-run, MCP shell access)

LLM app security (prompt injection, system-prompt exposure)

Runaway AI cost & missing token caps

Framework-specific rules across 24 frameworks

Each finding includes the file, line number, a plain-English explanation, and a suggested fix you can copy-paste.

## AI-Powered Deep Scanning

The free local scan uses rule-based pattern matching for instant results. Paid plans unlock AI-powered deep analysis that covers:

Auth logic flow analysis

Supabase RLS policy checks

Business logic review

Plain-English fix prompts

NOTE

AI-powered deep scanning is available on paid plans. CLI plans include 8–15 AI scans per month depending on your tier. See [pricing](https://ship-safe.co/pricing) for details.

## Scan a Specific Path

You can scan a specific file or subdirectory:

TERMINAL

Copy

```bash
npx @ship-safe/cli scan src/
```

TERMINAL

Copy

```bash
npx @ship-safe/cli scan server/api/auth.ts
```

## Connect to Your Dashboard

Log in to sync scan results to your web dashboard. Results auto-upload after every scan.

TERMINAL

Copy

```bash
npx @ship-safe/cli login
```

This opens your browser to authenticate. Once logged in, every scan automatically appears in your dashboard with full history and diff tracking.

On a subscription, a scan of a GitHub repository can also send its fixes to your GitHub for you to approve, with a receipt — see [Fix it for me, with a receipt](https://ship-safe.co/docs/fix-it-for-me).

TIP

**Tip:** Run `npx @ship-safe/cli whoami` to check your login status, or `npx @ship-safe/cli logout` to sign out.

## Create a Config File

Generate a `.shipsafe.yml` config file to customize which rules run and which files to exclude:

TERMINAL

Copy

```bash
npx @ship-safe/cli init
```

See the [Configuration](https://ship-safe.co/docs/configuration) docs for all options.

## Output Formats

ShipSafe supports three output formats:

### Table (default)

Human-readable report with colored severity badges, code snippets, and fix suggestions.

### JSON

Structured output for scripts and custom CI integrations.

TERMINAL

Copy

```bash
npx @ship-safe/cli scan . --output json
```

### SARIF

Upload to GitHub's Security tab to see findings inline on PR diffs.

TERMINAL

Copy

```bash
npx @ship-safe/cli scan . --output sarif
```

[Next →Fix it for me, with a receipt](https://ship-safe.co/docs/fix-it-for-me)

## Sitemap

Every page of this site, in markdown: [https://ship-safe.co/sitemap.md](https://ship-safe.co/sitemap.md)
